AU2003219752B2

System and method for acoustic two factor authentication

Abstract

Apparatus and method are disclosed for digital authentication and verification. In one embodiment, authentication involves storing a cryptographic key and a look up table (LUT), generating an access code using the cryptographic key; generating multiple parallel BPSK symbols based upon the access code; converting the BPSK symbols into multiple tones encoded with the access code using the LUT; and outputting the multiple tones encoded with the access code for authentication. In another embodiment, verification involves receiving multiple tones encoded with an access code; generating multiple parallel BPSK symbols from the multiple tones; converting the BPSK symbols into an encoded interleaved bit stream of the access code; de-interleaving the encoded interleaved bit stream; and recovering the access code from the encoded de-interleaved bit stream.

AU2003219752B2, drawing sheet 1
Sheet 1 of 1

Term

Term ended

Expired 12 February 2023, 3.6 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

31 claims: 18 independent, 13 dependent

  1. 1
    THE CLAIMS DEFINING THE INVENTION ARE AS FOLLOWS:1. A method for authentication, including: providing at least a PIN and a confidential public key to an authorizing computer;5 establishing a communication link between the authorizing computer and at least one receiver remote from the computer, the communication link not being constrained to be secure;receiving, at the receiver, at least one acoustic signal representative of at least one private keygenerated signal, the receiver transforming the acoustic signal to a signature signal;receiving, at the receiver, the PIN, the PIN being received separately from the acoustic signal;0 encrypting the signature signal with the PIN to render an encrypted signature signal;and sending the encrypted signature signal to the authorizing computer for verification of the signature using the PIN and confidential public key.
  2. 2
    The method of Claim 1, wherein the act of encrypting is undertaken at the receiver.
  3. 3
    The method of Claim 1 or 2, including transmitting the acoustic signal using a hand-held token.
  4. 4
    The method of any one of Claims 1 to 3, further including inputting a desired transaction to 0 the receiver, the authorizing computer authorizing the receiver to execute the transaction only if the signature is verified.
  5. 5
    The method of any one of Claims 1 to 4, wherein the signature is verified by:decrypting the encrypted signature signal using the PIN to render the signature signal;then 25 verifying the signature signal using the confidential public key.
  6. 6
    The method of Claim 3, wherein the token generates a signature signal by combining at least one message with the private key. 30
  7. 7
    The method of Claim 6, wherein the message includes at least a portion of at least one timestamp.
  8. 8
    The method of Claim 7, wherein the portion of the timestamp is a predetermined number of least significant bits of a timestamp having more bits than the predetermined number. 2003219752 01 May 2008
  9. 9
    A system for two-factor authentication over a link not constrained to be secure, including:at least one portable token generating at least one wireless signal representing a digitally signed message;at least one receiver receiving the wireless signal and a PIN, the PIN being received separately 5 from the wireless signal, the receiver encrypting the signed message with the PIN to render an encrypted signed message;and at least one authorizing computer receiving at least the encrypted signed message over the link, the authorizing computer accessing the PIN and a confidential public key to attempt to verify the signed message.
  10. 10
    The system of Claim 9, wherein the wireless signal also represents at least an ID of a confidential public key and a message that was signed by a private key corresponding to the public key to render the digitally signed message. 5
  11. 11
    The system of Claim 10, wherein the receiver sends the encrypted signed message, ID, and message that was signed to the authorizing computer.
  12. 12
    The system of Claim 10, wherein the authorizing computer decrypts the encrypted signed message using the PIN and then verifies the signed message by accessing the confidential public key 0 using the ID and using the confidential public key.
  13. 13
    A system for authentication including an authorizing computer accessing at least a PIN and a confidential public key and communicating over a link with at least one receiver remote from the computer, the communication link not being constrained to be secure, the system including:25 means for receiving, at the receiver, at least one wireless signal representative of at least one digital signature produced from a private key, the receiver transforming the wireless signal to a signature signal;means for receiving, at the receiver, the PIN;and means for encrypting the signature signal with the PIN to render an encrypted signature signal, 30 wherein the encrypted signature signal is sent to the authorizing computer over the link for verification of the signature using the PIN and confidential public key.
  14. 14
    The system of Claim 13, wherein the means for encrypting are at the receiver. 35
  15. 15
    The system of Claim 13 or 14, including means for transmitting the wireless signal using a hand-held token. 2003219752 01 May 2008
  16. 16
    The system of any one of Claims 13 to 15, further including means for inputting a desired transaction to the receiver, the authorizing computer authorizing the receiver to execute the transaction only if the signature is verified. 5
  17. 17
    The system of any one of Claims 13 to 16, including:means for decrypting the encrypted signature signal using the PIN to render the signature signal;and means for verifying the signature signal using the confidential public key. 0
  18. 18
    The system of Claim 15, wherein the token generates a signature signal by combining at least one message with the private key.
  19. 19
    The system of Claim 18, wherein the message includes at least a portion of at least one timestamp.
  20. 20
    The system of Claim 18 or 19, wherein the message is further combined with a pseudorandom number.
  21. 21
    The system of any one of Claims 13 to 20, wherein the wireless signal is an acoustic signal. 0
  22. 22
    The system of any one of Claims 9 to 12, wherein the wireless signal is an acoustic signal.
  23. 23
    A computer readable medium containing instructions for controlling a computer system to perform a method, the method including:
  24. 24
    25 providing at least a PIN and a confidential public key to an authorizing computer;establishing a communication link between the authorizing computer and at least one receiver remote from the computer, the communication link not being constrained to be secure;receiving, at the receiver, at least one acoustic signal representative of at least one private keygenerated signal, the receiver transforming the acoustic signal to a signature signal;30 receiving, at the receiver, the PIN, the PIN being received separately from the acoustic signal;encrypting the signature signal with the PIN to render an encrypted signature signal;and sending the encrypted signature signal to the authorizing computer for verification of the signature using the PIN and confidential public key. 35 24. The computer readable medium Claim 23, wherein the act of encrypting is undertaken at the receiver. 2003219752 01 May 2008 25. The computer readable medium Claim 23 or 24, including transmitting the acoustic signal using a hand-held token.
  25. 25
    26. The computer readable medium any one of Claims 23 to 25, further including inputting a 5 desired transaction to the receiver, the authorizing computer authorizing the receiver to execute the transaction only if the signature is verified.
  26. 26
    27. The computer readable medium any one of Claims 23 to 26, wherein the signature is verified by:0 decrypting the encrypted signature signal using the PIN to render the signature signal;then verifying the signature signal using the confidential public key.
  27. 27
    28. The computer readable medium Claim 25, wherein the token generates a signature signal by combining at least one message with the private key.
  28. 28
    29. The computer readable medium Claim 28, wherein the message including at least a portion of at least one timestamp.
  29. 29
    30. The computer readable medium Claim 29, wherein the portion of the timestamp is a 0 predetermined number of least significant bits of a timestamp having more bits than the predetermined number.
  30. 30
    31. A method substantially in accordance with any one of the embodiments of the invention described herein and illustrated in the accompanying drawings.
  31. 31
    32. A system substantially in accordance with any one of the embodiments of the invention described herein and illustrated in the accompanying drawings. 1/1 WO 03/071770 PCT/US03/04387 FIG. 2
Independent claims31